CVE-2026-4113
Sonicwall Sma6210 Firmware ≤ 12.4.3-03387
Raw vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:HSummary
CVE-2026-4113 is a high-severity Observable Response Discrepancy (CWE-204) vulnerability in Sonicwall Sma6210 Firmware. Its CVSS base score is 7.2 (High).
Operationally, exploitation aligns with the MITRE ATT&CK technique Account Discovery (T1087); ranked at the 29th percentile by exploit likelihood (below the median); it is not currently listed in the CISA KEV catalog.
The strongest mitigations our analysis identified map to IA-6 (Authentication Feedback) and SI-11 (Error Handling) — see the control section below for these in your framework.
Deeper analysis AI-assisted summary
Synthesised by an AI model from the NVD description and linked references — a reading aid, not an authoritative source.
CVE-2026-4113 is an observable response discrepancy vulnerability, classified under CWE-204, affecting the SonicWall SMA1000 series appliances. It enables a remote attacker to enumerate SSL VPN user credentials by exploiting differences in server responses. The vulnerability received a CVSS v3.1 base score of 7.2 (AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H), indicating high severity due to its network accessibility, low complexity, and significant impacts on confidentiality, integrity, and availability.
Exploitation requires high privileges (PR:H), meaning an attacker must already possess an authenticated account with elevated access on the appliance, such as an administrator. From a network-accessible position, the attacker can send crafted requests to the SSL VPN component, observing response discrepancies to infer valid usernames and potentially passwords or other credentials. Successful enumeration could lead to full compromise of VPN access, enabling further lateral movement or data exfiltration.
SonicWall has documented the issue in their PSIRT advisory at https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2026-0003, published on 2026-04-09, which provides further details on affected versions and recommended mitigations. Security practitioners should consult this advisory for patching instructions and workarounds to address the vulnerability.
EU & UK References
- 🇪🇺 ENISA EUVD: EUVD-2026-20904
Vulnerability Data
An observable response discrepancy vulnerability in the SonicWall SMA1000 series appliances allows a remote attacker to enumerate SSL VPN user credentials.
- CWE(s)
Related Threats
MITRE ATT&CK Enterprise Techniques
CVEs Like This One
Affected Assets
Mitigating Controls
Control response
—
—
—
V13.4.5
Mitigating Controls (NIST 800-53 r5) AI
Obscuring authentication feedback directly stops one common source of observable response discrepancies.
Error handling explicitly requires messages that avoid revealing exploitable internal information.
Information flow enforcement can block responses that would otherwise disclose internal state to unauthorized parties.
Boundary protection monitors and filters outbound responses that could leak internal state.
Mitigating Controls (NIST CSF 2.0) AI
Derived directly from the weakness types (CWEs) cited in the NVD entry via our AI-authored CWE→CSF cross-walk (authority under review) — links open the control.
Secure SDLC practices directly prevent introduction of inconsistent response behavior that leaks internal state.
Mitigating Controls (ISO/IEC 27001:2022 Annex A) AI
Derived directly from the weakness types (CWEs) cited in the NVD entry via our AI-authored CWE→ISO cross-walk (authority under review) — links open the control.
Security testing can detect observable response discrepancies before deployment.
Network security controls can enforce uniform responses and suppress observable discrepancies.
Secure SDLC practices include error-handling and response standardization to avoid information disclosure.
Application security requirements typically mandate consistent, non-revealing error messages.
Secure architecture principles discourage designs that leak internal state via differing responses.
Secure coding standards explicitly require uniform error handling to prevent information leakage.